CyberRota Analysis
AI-GeneratedThe miniOrange 2FA plugin for WordPress versions prior to 6.2.7 is vulnerable due to improper binding of the second authentication factor during the pre-login challenge, enabling attackers with knowledge of a user's password to reconfigure the second factor to their own control. This flaw can lead to account takeover, including access to administrator accounts, posing a significant risk to site security. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this vulnerability.
Original NVD Description
The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the challenge, and take over the account, including administrator accounts.